Cyber risk management – a senior leadership responsibility

Author: Mitigo

Date published

4 April 2024

Cyber risk management – a senior leadership responsibility

Tag
Author
Date published
Price
Blog
Author

Mitigo

Date published

4 April 2024

Author

Mitigo

Senior business leaders must prioritise independent cybersecurity expertise to effectively manage cyber risks and protect stakeholder interests in today's escalating threat landscape.

Cyber risk management is a critical senior leadership responsibility, due to the escalating cyber threat landscape and the profound impact of cyber incidents on business operations, reputation, and financial stability. A ransomware attack can bring a business to an abrupt halt and in some instances close it down.

It is no surprise that so many business victims feel forced into paying the ransom demand when so much is at stake. Obvious high-risk sectors include professional services such as law firms, accountants, financial services businesses and any firm handling confidential data and transactional work. But the construction sector, healthcare sector, factories, car dealerships, retailers and so many others are at operational risk too.

All senior business leaders have a responsibility to manage their cyber risk to safeguard sensitive information, maintain operational continuity, and protect stakeholder interests. Leaving cyber risk management to their IT support simply does not cut it. Proper cyber risk management is a sophisticated stand alone discipline, covering so much more than just technology. It requires a comprehensive programme, with formal risk assessments, policies and procedures, and staff training.

Good cyber governance should include obtaining independent assurance from a cybersecurity specialist – someone who will assess and provide visibility of your cyber risks, determine the measures appropriate to control those risks, and give you ongoing assurance that the controls you have in place continue to be effective.

There are two key aspects to ensuring success:

· Independence – because having IT mark their own homework is a nonstarter when it comes to good risk management.

· Expertise – because cybersecurity is complex and ever-changing, and you need a specialist who understands your business structure and the current methods of attack, as well as your legal and any regulatory obligations.

Cyber breaches do not result from bad luck. A serious breach means that someone at the most senior level has failed to understand what was required to protect their business and has not done their job properly. And if you haven’t yet assigned responsibility to someone at Board level, your business really is living on borrowed time.

We have partnered with Mitigo to offer cybersecurity risk management services with exclusive discounts for our members.

For more information about Mitigo’s Cybersecurity services, call 020 8191 1590 or email [email protected]  

Additional information

Format:
Blog
Publisher:
IStructE

Tags

Blog Other

Related Resources & Events

Report
Blue abstract blocks

EEFIT Mission report: Turkey earthquake sequence February 2023

This EEFIT Field Mission report, and extended summary in Turkish, details the effects of the Mw 7.8 and Mw 7.5 earthquakes which struck southeastern Turkiye and northern Syria on 6 February 2023.

Date – 6 February 2024
Author – Various
Price – Free
Blue abstract blocks

Build Change: The engineer’s role in improving global housing resilience

This lecture provides an overview of the global challenges to resillient housing and proven solutions for risk reduction.

Date – 11 January 2024
Author – Louise Foulkes, Build Change
Price – Free
Training
Blue abstract blocks

EEFIT research grant showcase lecture II 2023

Annual grants supporting short-term projects that benefit earthquake disaster mitigation and post disaster reconnaissance efforts.

Date – 18 September 2023
Author – Konstantinos Skalomenos, Nurullah Acikgoz and Chenbo Wang
Price – Free